The Roundtable
← The library  ·  Study two
Published 27 July 2026 Reading time ~35 min · four interactive machines Status Refereed · accepted Seats convened Economics & Statistics Referee · Game Theory & Mechanism Design · Institutions & Commons · Technology & AI Governance · Earth-Systems & Ecological Science · Complex-Systems & Polycrisis
The Roundtable · Study 02 · Reading edition · Published 27 July 2026

The keys to orbit

Who controls low-Earth orbit — by law, or by physics? And how close is the collision cascade? A structural occupancy study. Not a forecast.

New here? Be shown, not told. The 10-minute guided tour flies you from one crowded shell down to the crews, through the heat wall and a real collision — then hands you this page for the detail.

In one paragraph. One company — SpaceX — now operates roughly two of every three active satellites1 through its Starlink constellation, concentrated in a handful of thin orbital shells that everything bound for higher orbit must cross. The result is a new kind of gatekeeping — enforced not by any treaty but by collision risk itself. Meanwhile the crowding has a measurable stress reading: if every satellite stopped dodging tomorrow, the expected time to a possible collision is now measured in days, not months2. This study maps who holds the keys at each altitude, and puts honest error bars — two bands, never one false-precision number — on how close the cascade is.

What this study is: a snapshot of structure and exposure, with every number traceable to a public catalog, a cited source, or a seeded simulation you can re-run. What it is not: a prediction of when, or whether, a collision happens.

1 · The ascent gauntlet

Orbit is not one place; it is a stack of rings with radically different physics. Reaching anything above — navigation satellites, the Moon — means crossing every ring below. The cost of crossing changes in kind as you climb: coordinate (a maneuverable operator you negotiate with), endure (an un-owned debris field you survive), comply (a disposal norm).

Explore the column: seven floors of the same thin sky. Blue floors self-clean — thin air flushes mistakes in months to years; amber floors keep their mistakes for decades to centuries. Flip "everyone stops dodging" and watch which calm was physics, and which was only effort.

In plain terms: the busiest shell and the most dangerous debris are not at the same altitude — and neither behaves the way you'd guess. In the paper: §2.2–2.3 · §3 · §4.2–4.3.
The two loops that decide the shell: collision-production and drag-removal A causal-loop diagram. The stock is objects in the shell. A reinforcing loop runs to the right: more objects raise the collision rate, which creates fragments, which add to objects. A balancing loop runs to the left: more objects feed atmospheric drag and re-entry, which removes objects — but only after a delay of months at low altitude to centuries at high altitude. Objects in the shell satellites + debris Collision rate Fragments created + + + R Atmospheric drag → re-entry + delay B R reinforcing (Kessler): fragments beget collisions beget fragments. B balancing (drag): air pulls objects down. + same direction · − opposite · ∥ delay — months low → centuries high (why amber floors keep mistakes).
In plain terms: two forces, one shell. Collisions make fragments that cause more collisions (the reinforcing engine); thin air drags objects back down (the brake) — but the brake acts on a lag that stretches from months down low to centuries up high. Where the lag is long, the reinforcing engine can win. In the paper: §3 (the substrate) · §4.1–4.3 (the stock-flow engine).

2 · Who holds the keys

The occupancy picture, measured from the public satellite catalog (32,010 tracked objects, 15 July 2026) MEASURED:

QuantityValueBasis
Starlink objects in catalog10,742catalog name-lines MEASURED
— as share of all cataloged payloads54.7%workbook, live formula — cataloged payloads include the dead; the active-only share is 66.1%, below
Next largest constellation (OneWeb)654MEASURED
Active payloads, all operators16,234McDowell census, 8 Jul 2026 SOURCED
Non-maneuverable active payloads2,113census, 8 Jul 2026 SOURCED — the burden-shift population
Starlink collision-avoidance maneuvers, Jun–Nov 2025148,696SpaceX FCC report11 SOURCED
In plain terms: for every satellite anyone else flies, Starlink flies two — and its fleet performs a collision-dodge every couple of minutes, around the clock. Nobody voted on this arrangement; it emerged one launch at a time.

The keys were minted by occupation

The keys to orbit were never issued by any treaty — no law anywhere requires anyone to coordinate with SpaceX. They were minted by occupation and they are enforced by collision risk: the shells sit across the ascent path, maneuvers invalidate everyone else's orbit predictions for days3, and ignoring SpaceX prices itself. Stated precisely: the requirement to coordinate is physically generated — by occupancy; risk-economically enforced; and legal almost nowhere. No operator-level coordination duty exists in any binding instrument.

One caveat keeps that honest, and the study carries it everywhere: "physics" alone would naturalize a chosen arrangement. The corridor is hazardous without coordination only because a voluntary, reversible deployment pattern made it so — and it stays passable only because a private operations room keeps it so. Physics is the enforcement; occupancy is the source; operations is the maintenance.

Same entity, five bases (never mixed in one figure)Starlink share
Tracked LEO objects (weighted, incl. debris)38.7%
Active payloads (census, 8 Jul 2026)66.1%
Operational-satellite mass (May 2023 — stale)52.0%
Trigger-band payload density (465–495 km — the band where a cascade would most likely trigger; §3)95.0%
No-maneuver collision rate (Starlink-involved)97.9%
In plain terms: "how big is Starlink" has five honest answers, from 39% to 98%, depending on what you count. A reader shown one number unlabelled will misinfer the others — which is why every figure in this study names its base. (The mass figure is also where a peer-reviewed source's own abstract slipped: 52% is of operational-satellite mass, not all mass in orbit.)10 MEASURED SOURCED per row; referee-verified9.
The density-ratio scale curve: how many times denser the trigger band is than the debris peak, by comparison-window size Seven points from 1 km to 50 km windows. At 1 km the ratio reads 56.9 — a discretization artifact of sub-kilometre slots, retired. The curve falls steeply and flattens into a plateau near 20 to 30 km; at the source's own 30 km shell convention the ratio is 11.1, which is the number the study carries. At 50 km it is 6.8. One comparison, seven answers — the ratio depends on the ruler 10×20×30× 40×50× 56.9× at 1 km — a discretization artifact (sub-km slots flatter the numerator; retired) 11.1× at 30 km — the carried number (the source's own shell convention) the plateau: 20–50 km all read ≈7–12× — scale-stable 1 km3 km5 km 10 km20 km30 km 50 km width of the comparison window (trigger band vs the 800-km debris peak, both measured identically) MEASURED (2026-07-15 catalog; matched-scale sliding window, volume-weighted) · window sizes evenly spaced as labeled.
In plain terms: zoom in far enough and any comparison flatters the numerator. The honest ratio names its ruler.

December 2025: the thread that connects everything

On 9 December 2025 a Chinese Kinetica-1 launch deployed nine satellites without — SpaceX says — coordination; on 12 December one passed within 200 meters of Starlink-6079 at 560 km4. Chinese researchers counter that trajectory data arrived ~14 minutes before closest approach. Within three weeks, SpaceX announced it would lower ~4,400 satellites from 550 to 480 km, explicitly citing safety reconfiguration5. By July 2026, the catalog shows the move nearly complete: the fleet now concentrates near 490 km — at the 1-km slot scale, nearly eight times its old peak density; averaged over the full 30-km shell, about twice MEASURED. One uncoordinated launch reshaped the geography of low-Earth orbit — and, as §3 shows, reshaped the risk math with it. The episode is also this study's natural experiment in law: an uncoordinated approach to 200 meters violated no enforceable obligation, triggered no venue, and was litigated entirely by press statement. If the compulsion were legal, that event would have had a legal life. It had none.

An unchartered utility

What kind of institution is this? The closest terrestrial analogs are not lighthouses but essential private infrastructure operating ahead of the institutions that later wrapped it — railroads before the regulators, private clearinghouses before central banking. A utility performs a function the public cannot do without; a charter is what makes depending on it tolerable: service obligations, continuity requirements, exit terms. Orbit has the utility and none of the charter — no service obligation, no rate terms, no exit conditions, no accountability for the safety function itself. In commons terms the structure is inverted twice over: SpaceX is the largest appropriator on all five disclosed bases and the sole large-scale provider of the safety infrastructure, while holding no appropriation rights (treaty law forbids title) and no provision obligations (nothing requires the maneuvering to continue).

That second inversion is the study's sharpest institutional finding: the continuity gap. A shutdown — commercial failure, sanction, war — is, institutionally, the operator-insolvency scenario, and no institution on Earth currently has both the jurisdiction and the funds to keep the suppression running through it. A bankruptcy estate optimizing creditor recovery has neither mandate nor budget for orbital safety. The engine prices what is at stake in that gap: five years after a launch stop, walking away leaves 73,113 tracked fragments in the trigger band; a responsible wind-down — deorbiting on the way out — leaves 2,407. Thirty times less debris, from institutional tidiness alone MODELED (paired draws; disposal compliance assumed 0.85–0.97, untested at fleet scale; magnitudes conditional on f_imp — the assumed fraction of dangerous close passes that become collisions; see the glossary).

The study does not stop at naming the gap. The paper now sketches the institution that would close it — call it a continuity regime (the paper's E6): a trip-wire that watches whether a fleet is still steering, not whether its owner is still solvent — so it can act while a distressed operator is still flying, not only after it walks away — paired with a ring-fenced fund, posted in advance and held outside the company, whose one job is to bring a failing fleet down. One honest piece is still missing: no third party can yet fly someone else's dead fleet down, so the design leans on catching trouble early, while the operator can still steer its own. And only one of its costs can be priced today — roughly $759 million to retire the largest fleet, and that is a floor, the smallest of several bills (flying the fleet through the wind-down, audits, independent tracking are all unpriced), never "the price of continuity" FLOOR MODELED. The avenues table in §6 places it against everything else on the board.

See the fork: same shutdown, two endings — walk away, or steer the fleet down on the way out. Slide the years and watch the two futures separate.

The continuity gap, made touchable: at year five, ≈73,000 tracked fragments from walking away versus ≈2,400 from a steered exit — the measured value of one boring institution. Or play the whole fifty years, band by band, in the guided tour's finale. In the paper: §4.4 (exit asymmetry) · §5.4 (the continuity gap) · §7.3 (the continuity regime, E6).
Who supplies the safety
  • ~800 collision-avoidance maneuvers a day — one every ~1.8 minutes, around the clock — performed by SpaceX, for its own Starlink fleet
  • 10,736 active satellites' worth of collateral parked in the same band the maneuvers protect
  • a maneuver threshold ten times more conservative than the industry standard
Who consumes it, unasked and unbilled
  • every ascent to anywhere higher — one 30-km band holds 30.5% of the whole ascent column's population
  • 2,113 active satellites that cannot maneuver at all
  • the station crews below, in the path of everything that comes down
In plain terms: SpaceX dodges for its own fleet, and everyone else's safety rides along as a side effect — with no bill, no contract, and no promise it continues. The parties with the least agency in the corridor bear the residual risk of arrangements they had no voice in.

3 · How close is the cascade?

The honest instrument here is the CRASH Clock (Thiele, Heiland, Boley & Lawler, 2026): the expected time to a possible collision if all collision-avoidance stopped — a stress gauge, not a prediction. Their published value: 164 days in 2018; 5.5 days by June 2025; 2.5 days by May 20262 SOURCED.

In plain terms: in 2018, orbit could run on autopilot for months before the dice got dangerous. Today it's days. The system works — but only because nothing is allowed to blink.

Our reproduction — and what the number actually means

We reimplemented the published method independently, reproduced the paper's numbers to within rounding, then ran it on the 15 July 2026 catalog. The one honest number to carry: if collision-avoidance stopped today, the median wait to a first collision is about four days (modeled median ~4.1, range 2.9–5.7) DERIVED. Not hours — and not the sub-one-day figure the raw slot-scale rate alone would suggest.

In plain terms: today's orbit, flown without maneuvering, would likely see its first collision within a working week — where in 2018 it could have coasted for months. A constellation flown in tidy, managed slots is deliberately deconflicted, so the danger starts lower than the raw crowding implies and climbs only as that order decays, over days to weeks.
The sub-day figures behind that median — and why we never average them

The reproduction yields two rate figures, answers to two different questions, never averaged into one MEASURED:

RunRate (days)What it answers
A — as-binned (real slots)0.71the loss-of-control asymptote: the rate orbit relaxes toward once tidy slot order decays
B — shell spread over 30 km1.75a design counterfactual: altitude spreading is a safety lever worth a measured 2.785× on the in-shell clock — a finer cut than this table's two rates, whose own ratio is ≈2.5×

The ~4-day median is the realistic wait from a standing start: at the instant control is lost, collisions are far rarer than the asymptote implies; the rate climbs toward it as orbital order decays (along-track phasing first, over days to weeks). The study's stock-flow engine, using a mixing time built from the measured slot dispersion, puts T_mix at ~16 days (range 8–31) and the median first collision at ~4.1 days (range 2.9–5.7), against 0.49 at the asymptote — 0.49 is the 0.71-day clock restated as a median: the clock is the mean wait, and a random wait's median is the mean × ln 2 scale ASSUMED. The 0.71-day figure is the destination, not the doorway.

Where the risk actually lives — two bands, two different dangers

Decomposing the no-maneuver rate by altitude MEASURED: under either treatment, the probability of a first collision lives overwhelmingly at the 480 shell (92% / 81% of the total rate; essentially all satellite-on-satellite), while the legacy debris band at 700–1,000 km carries ~1% of the trigger rate — but all the persistence. Each band earns a precise name. At 465–495 km, a fuel-limited transient cascade is possible — a genuine runaway chain while the intact fleet (the fuel) lasts: fast, self-extinguishing, its fragments flushed by drag within months to years; and the credible fast risk there is operational — screening and maneuver capacity saturating — which is severe but reversible once capacity recovers. At 700–1,000 km, where drag removes nothing on policy timescales, crossing the production-exceeds-removal threshold12 is an effectively irreversible ratchet: reversal requires actively hauling debris out, not merely stopping. Regime-shift language belongs to that band alone — and debris settling there today commits decades of future flux down through the operating and crewed bands: classic overshoot structure, spending now, paying later.

In plain terms: the crowded new shell is where a crash is most likely to start — a fire that burns hot but burns out. The graveyard band above is where wreckage stays — a ratchet that only turns one way. Two dangers, two altitudes, and only one of them is forever. Most public discussion blurs them into one word: "Kessler."

See it move: the guided tour throws a corridor collision's wreckage three ways at once — up (a visit, not a stay), down (a pulse the air digests), sideways (a ring in days) — on a clock you drag.

The two-band treatment (floor = today's snapshot; coupled = elevated-rate storm scenarios) is built, seeded, and independently verified. Its knobs are ASSUMED — the elevated rates are assumed storm forcing, not measured feedback — so no coupled headline number appears here: publishing one now would be false precision. The quantity that actually decides subcritical vs supercritical is the loop gain, and that is the tunable knob of the fuller cascade engine this study's stock-flow model is the floor of.

4 · The filing race

The forward risk is not today's catalog; it is the queue — and the central finding here is that two different games are being played here, and they must never be blurred: a filing race on paper, and a deployment race in hardware. The first is real, observable, and mild. The second is conditional — and it is where the danger lives.

Game one: the paper race

A dated sequence, each item docket-anchored15 or tagged SOURCED:

Date (2026)Event
Jan 30SpaceX files for up to 1,000,000 orbital-data-center satellites (SAT-LOA-20260108-00016)
Feb 4FCC Space Bureau accepts (DA-26-113); ~30-day comment window
Mar 6Amazon petitions to deny SpaceX's application
Mar 19Blue Origin — same beneficial owner as Amazon — files "Project Sunrise": up to 51,600 satellites, 500–1,800 km
Mar 20–23SpaceX asks the FCC to apply Amazon's objections to Blue Origin's filing (reported)
May 12NASA — a federal user of the corridor — objects to Blue Origin's filing (reported)
Jun 24Orbital Compute (5-month-old startup) files for up to 100,000 satellites
Jun 30SpaceX files "+100k Gen3" (SAT-LOA-20260630-00264), two shells at 323–327.5 and 473–477.5 km

Formally, this layer is a preemption game in which "file big" is close to a dominant move: filing costs almost nothing relative to the stakes, a filing acquires option value, and abstaining while rivals file costs junior queue status. The sequence above — petition to deny a rival, then file the same concept under one's own name thirteen days later, from the same beneficial owner — is not hypocrisy; both moves are best responses, and playing both is the cleanest tell in the record that the behavior is structural, not moral. The filing race by itself is rent-seeking, not tragedy: its direct harms are a distorted queue and a polluted docket. What a filing buys is also worth naming precisely, because there are two priority currencies: legal spectrum priority (queue seniority — what the filing formally acquires) and physical volume priority (occupation — which no law grants, because treaty law forbids title to space itself17, but which engineering makes absolute: a later entrant cannot fly where an incumbent already flies). The paper race is legally a race for the first currency6.

The accelerant: machinery that converts paper into hardware

The conversion between the two games is built into the rules meant to police the first one. Holding a filing is nearly free (one satellite, maintained ninety days, keeps an entire system's spectrum claim alive). Holding an authorization is expensive in exactly one direction: deployment milestones — 10% of a system within two years of the regulatory deadline under the international rules; 50% within six years under the US rules — enforced by bonds forfeited on a missed milestone or on surrender, so even walking away is penalized6b. Conditional on grants, option-holders are converted into builders on a regulatory clock. The diagnosis: this is anti-warehousing machinery pointed at a physical-externality problem — it polices the mild harm (claims without satellites) with an instrument that maximizes the severe one (satellites without demand). A deadline forces deployment even when realized value turns out low; a holding price would let low-value claims die quietly.

The spectrum clock (paper) filing 1 satellite, 90 days holds the whole claim cheap to hold — the paper can wait at a grant, the claim moves to the clock below — the deadline then builds hardware on regulation's schedule, not demand's. The hardware clock (steel) grant milestone: 10% milestone: 50% milestone: 100% deploy-or-forfeit bond — forfeited even on surrender Rule texts verified (ITU RR 11.44/11.44C, Res. 35; 47 CFR 25.164/25.165).
In plain terms: the rules make it cheap to claim and expensive to wait. Once a claim is granted, the clock forces satellites into orbit whether or not the business case shows up. The machinery built to stop paper hoarding is what turns paper into hardware.

Game two: the deployment race, mapped

Whether the hardware race becomes a genuine trap depends on a payoff nobody has demonstrated: whether orbital data centers (or any of the filed concepts) actually make money net of ordinary costs. The study's race model does not pretend to know. Instead it sweeps the whole space of assumed payoffs and maps the regions7. Over that swept box: roughly 69% is paper — the business case fails on ordinary cost, and the mountain of filings never becomes hardware; 17% is a race that stays below the physical threshold; 14% is the trap — profitable deployment that carries the shell past it shares of ASSUMED payoff space — parameter belief over payoff assumptions, never probabilities of the future.

Walk the map: across is what a satellite-year is worth; up is how much the world wants. Every point is a possible world — grey where the paper never flies, blue where fleets build and stay under the line, amber where they build straight past the cliff. Run your pointer across it, and tap to park a satellite where you think the world lands.

In plain terms: the model cannot say which world is ours; it says what kind of map we are walking on — and on most of it, a market that overshoots "by a bit" overshoots the physical line. Prefer it narrated? The guided tour walks the same deployment race — one launch, the crowded shell, the heat wall. In the paper: §6.3 (the race model) · §6.4 (the thin middle).

The map's structure matters more than its shares. (The percentages that follow are three different cuts of the same swept box — by outcome above, by reachability and by margin here — not slices of one pie.) In 45% of the box the threshold is unreachable — demand saturates below the cliff no matter how hard the race runs. But where the cliff is reachable, the profitable window under it is razor thin: the demand level that makes deployment pay and the level that crosses the threshold typically sit within a factor of two of each other (74% of reachable draws). And the private cost of standing at the cliff edge is a few hundred dollars per satellite-year — against business cases denominated in tens or hundreds of thousands — so the market's own feedback is deterrence-relevant in well under 1% of cases. In the model's words: the race either fizzles or overshoots; nothing in it is calibrated to stop at the line. The equilibrium is not malicious — it is indifferent to the cliff, because the cliff never shows up in anyone's ledger. The honest form of the danger claim, and the only one this study makes: the collision externality is unpriced, therefore whatever entry occurs is over-entry — never "a million satellites will fly."

The milestone arithmetic — an illustrative ceiling, standing on three loud IFs. Filed systems to date total 1,251,600 satellites. IF every filing were granted, IF each honored only its first international milestone (10%), and IF that stock concentrated at trigger-band-like shells, the resulting fleet — 12.7× today's — would exceed the modeled maneuvered threshold in 74% of the engine's parameter draws; at the US 50% milestone (59× today's), in 99% filings MEASURED threshold MODELED (parameter belief over assumed knobs, never event odds; f_imp-conditional). The IFs are load-bearing and the filings span 150–2,000 km, not one shell: this is column arithmetic under the machinery's own rules, not a band forecast — and it carries no dates, only distance to a threshold. Filings are options, not fleets.

The heat problem — the wall every filer has to clear

The objection everyone raises first is the right one: a data center in orbit must radiate away every watt it draws — no air, no water, only infrared glow into vacuum — and radiator area is the textbook bottleneck. What do the filings say about it? Three of the four say nothing — the million-satellite filing omitted thermal design entirely (its numbers surfaced months later, in an investor-facing reveal after the comment window had closed), and Blue Origin's 51,600-satellite filing states no cooling approach at all. The one filer with docket numbers, Orbital Compute, implies a radiator shedding heat at ~1,000 W/m² — roughly six times the International Space Station's radiators (≈166 W/m²), with the million-satellite figures pointing nearer eight times flight heritage ISS SOURCED filer figures DERIVED/CLAIMED at scale UNVERIFIED.

The heat wall: watts shed per square metre, and the radiator a 150 kW bus claims versus needs Panel one, heat flux: the ISS radiates a flight-proven 166 watts per square metre; Orbital Compute's 100 kW bus implies about 1,000, roughly six times ISS; the 150 kW million-satellite figures point near 1,330, about eight times. Panel two, radiator area at 150 kW: the filing claims about 110 square metres; at flown ISS density it would need about 900. Watts shed per square metre — the wall flight-proven line ISS radiators 166 W/m² · flown Orbital Compute · 100 kW ~1,000 W/m² · ≈6× SpaceX ODC · 150 kW ≈8× The radiator a 150 kW bus claims vs. needs claims ~110 m² needs, at flown density ≈900 m² Blue Origin (51,600 satellites) and the million-satellite filing stated no cooling at all — three of the four big filings leave the wall's one number blank. Per satellite; the queue holds up to a million. ISS SOURCED (NASA) · filer figures DERIVED/CLAIMED · at scale UNVERIFIED · implied flux = power ÷ claimed area; needed area = power ÷ 166 W/m².
In plain terms: the whole concept lives or dies on one number — watts shed per square metre — and it runs six to eight times anything ever flown. See it to scale, with a power dial you can turn, in the guided tour: the ISS beside a filed compute bus and the radiator field each would actually need. In the paper: §7.4 (the filings) · §6.3 (radiator claims).
In plain terms: the whole concept lives or dies on shedding heat — and that is exactly the number the biggest proposals leave blank. Where a figure does exist it describes a radiator nobody has built or flown: not impossible (a deliberately hot-running chip could get partway there), but unproven at scale, and the study tags it that way throughout. The claim is narrow — not "it can't be done," but that the filings ask to skip the queue before showing they can clear the one wall the physics puts up. The full read on the filings — every disclosed and omitted number, filer by filer — lives in the research paper.

Interlude · What comes back down

Everything launched eventually returns — and a satellite does not land, it burns, depositing its metal high in the atmosphere. So the filing race has a second ledger: not only what crowds orbit, but what rains back down. By sheer tonnage, today's whole fleet is a rounding error against nature — the sky already receives thousands of tonnes of meteoric rock a year13, and every returning satellite together is a fraction of it MODELED.

But bulk mass hides the sharper — and measured — finding: for several specific metals (aluminum, lithium, copper, lead), reentry-attributed mass already exceeds the meteoric source at today's fleet size, no buildout required, and reentry metals now turn up in roughly one in ten stratospheric particles sampled directly by aircraft14 MEASURED. The tonnage is small; the composition is not what the upper atmosphere evolved with. And the same milestone tiers that stress the orbital commons above would, if flown, push even the bulk rain into — and past — nature's own range. What the metal does up there — the modeled ozone and circulation claims, neither yet measured as a realized consequence — is weighed in the paper, §4.7.

Weigh the rain: today's fleet against nature's yearly infall of rock, bracket against bracket — then switch on the milestone IF-tiers and watch our rain of metal climb toward, and past, the natural range. Pick whose rain to watch.

In plain terms: by weight we are still a fraction of the sky's natural rain — but only until the filing queue flies, and already not by composition. In the paper: §4.7 (what comes back down) · §6.3 (the milestone IFs).

5 · The strongest counter-case

Honesty requires the other side at full strength: Starlink's collision-avoidance record is clean to date, at a maneuver threshold ten times more conservative than the industry standard (collision probability 1-in-100,000 vs the usual 1-in-10,000); the move to 480 km cuts debris lifetime from years to months and was undertaken voluntarily; launch-cost collapse has democratized orbit as much as enclosed it; and the connectivity — rural, maritime, wartime — is real public value. The strongest version of this case reads the maneuver burden not as gatekeeping but as SpaceX carrying the commons' safety load. The study presents both readings and lets the structure speak.

The study gives the counter-case a sharper engine than either "gatekeeper" or "hero": the stewardship is real and incentive-explained. While the fleet is in the band, SpaceX is what economists call a privileged group — its private benefit alone pays for the public good, so the safety needs no mechanism, no altruism, and no oversight to be supplied. The fleet itself is a bond posted in kind: 10,736 satellites of collateral against its own carelessness. The clean record is structure, not virtue — which is the strongest version of the counter-case, and it cuts both ways: the same structure that explains the record explains why it is unsecured. The arrangement is incentive-compatible exactly as long as the fleet is worth protecting; the shutdown scenario in §2 is what the incentive shock looks like.

The structure also quietly disables the top of the enforcement ladder. A regulator cannot credibly threaten anything harsh enough to induce exit — ordering the fleet dark, revoking to the point of abandonment — because executing the threat inflicts the abandonment scenario on the regulator's own constituency. Sanctions are structurally capped below the exit-inducing level: too-big-to-fail, orbital edition MODELED consequence — a structure result, not event odds. The cap is not total helplessness — leverage over future filings, grants, and queue position remains real and repeated — but the heaviest tools on the shelf cannot rationally be used.

6 · Avenues

Every avenue below carries an evidence tag in the Institutions seat's discipline: Demonstrated — a real institution with a measured record; Modeled — works on paper, incentive structure specified; Aspirational — a hope without an incentive structure yet. The map's headline, before the rows: everything now in force supplies monitoring and norms; everything that would price, bond, or guarantee continuity is modeled only — zero implementations anywhere on Earth as of this writing, and zero pre-existing debris objects ever removed by anyone. The commons currently has eyes and manners, and no ledger and no will.

AvenueEvidenceWhat it addresses — and the honest caveat
Mitigation guidelines (IADC/COPUOS)Demonstrated Debris generation at the margin; ~90% compliance with the 25-year disposal rule is real institutional achievement. Caveat: voluntary, no sanctions — and the international guideline is still 25 years; the 5-year rules are US (FCC, 2024) and European standards, not IADC.
Shared traffic awareness (TraCSS, EU-SST)Demonstrated The precondition for every other avenue: shared situational awareness, operational in beta. Caveat: monitoring without sanctions, and documented funding fragility — the system survived a near-termination this fiscal year.
Operator self-organization (data-sharing pacts, charters)Demonstrated in embryo The bottom-up path commons scholarship would predict. Caveat: untested as a constraint, and it fails at the geopolitical seam — where domestic security law forbids the private fix.
Responsible wind-down / continuity regime E6Demonstrated architecture · Modeled plan · Aspirational bridge The single point of failure §2 names — and the one avenue with a measured (in-model) value: 30× less trigger-band debris at year five than abandonment MODELED. The paper now designs it (E6): a function trip-wire on whether the fleet is still steering (every part demonstrated in bank supervision18; the threshold is modeled), a pre-funded bankruptcy-remote disposal trust (the decommissioning-trust model, demonstrated architecture; ~$759M to retire the largest fleet, a floor and the smallest of four cost lines FLOOR), a filed wind-down plan (the bank living-will model; no fleet instance exists yet), and a bridge operator to fly a failed fleet down — aspirational for a physical reason: third-party fleet-scale disposal exists nowhere (mid-2026: zero derelicts removed by a servicer). The US 5-year disposal rule is the per-satellite embryo. The cheapest real move on the board, alongside the bond inversion below.
Disposal bonds (dispose-or-forfeit)Modeled The abandonment failure mode, per satellite. The model is decisive at the unit level: disposal jumps from 0% to 100% when the bond at stake reaches the disposal cost (median ≈ $71k/satellite). Caveats that carry the design: the only bonds in force are deployment bonds — deploy-or-forfeit, i.e., accelerant machinery — and at cap scale they amount to ≈ $50/satellite, three orders of magnitude short; the reform is inverting the trigger, sizing to disposal cost, and escrowing outside the bankruptcy estate (a bond inside the estate is a creditor claim, not a mechanism).
Orbital-use feesModeled The unpriced density externality — the deployment-race margin. The economics literature prices the optimal path at ≈ $235k/satellite-year by 20408; our model adds the sobering geometry: the fee that holds the shell below its threshold has median ≈ $339k and only 41% of trap cases are held even at the top anchor — while the static distortion is nearly invisible (≈ $231/sat-yr), because essentially all the danger lives at the threshold, which static prices do not see. Caveats: zero uptake anywhere; no international levying authority exists; per-flag versions leak.
Milestone-clock redesign: deadline → holding priceModeled (proposed this round) The accelerant itself. The model's refinement: deadlines barely change how much hardware gets built — they change which: 2–3× more deployed capacity ends up stranded in negative-value states under deploy-or-lose than under a holding price, and the multiple grows with exactly the business-case uncertainty this race maximizes. Achievable US-side within existing authority; international side is treaty-speed.
Per-shell occupancy caps ("cap the shell")Modeled per-flag · Aspirational globally The stock-layer complement: cliff-shaped damage plus huge dispersion in the boundary-holding fee is the textbook condition where quantity instruments beat prices. The adopted pair — price the paper, cap the shell — splits the instruments across the two games. Feasibility: workable at the single-regulator level today — the cap binds at the licensing queue, the public catalog is a free compliance registry, and 95% of the trigger shell plus the whole filed queue sit in one jurisdiction — with two caveats that must travel with it: a cap grandfathered at today's occupancy without a decay path is the incumbent's moat, not a fix; and the coverage window closes as constellations outside the club grow.
Maneuver-capability mandatesDemonstrated per-flag · Aspirational cross-flag Growth of the unprotected stock — the 2,113 satellites that cannot dodge anyone. Narrow and cheap. Caveats: binds future entrants of compliant flags only; does nothing for the standing stock; raises small-actor entry costs.
Active debris removalModeled · Aspirational at scale The only lever for the 700–1,000 km ratchet band, where crossings are effectively irreversible — that is ADR's correct address, not the trigger band. Caveats: zero objects removed to date (demonstrated capability = a 15-meter inspection approach)16; the dual-use trust problem is unsolved; and removal without incentive reform recovers ≤ 9.5% of the lost value8.

One tested sentence ties the table together: no single instrument unpicks both games. Run through the model, the fee moves the deployment boundary and nothing else; the holding price moves the paper-to-hardware conversion and nothing else; the bond moves the end-of-life outcome (completely, once sized right) and the deployment margin only slightly. An avenue portfolio is not a rhetorical hedge here — it is what the coverage matrix says is required.

In plain terms: the rules that exist watch and advise; the rules that would bill, bond, or guarantee an orderly exit exist nowhere yet. None of the fixes is fictional — several are cheap and one is decisive on paper — but every one needs a decider, and the treaty architecture assigned that job to no one.

7 · Established vs. not established

Established (traceable to catalog, cell, or cited source)
Not established (and not claimed)

Glossary

Multipolar trap — a race in which each player's safest individual move makes everyone collectively worse off, and no one can exit alone without losing position. The study finds one conditionally: only if the deployment business case is real.
Unchartered utility — (working name) a private actor performing essential infrastructure work with none of the obligations a charter would attach: no duty to serve, no continuity requirement, no exit terms.
Privileged group — a situation where one actor's private benefit alone justifies paying for a public good, so it gets supplied without any agreement. Explains the maneuver record without heroism.
Holding price vs deadline — two ways to stop claim-hoarding: charge rent on a paper claim (low-value claims quietly die), or set a use-it-or-lose-it clock (low-value claims get built anyway). The rules in force chose the clock.

Conjunction — a close approach between two objects in orbit. "Close" here can mean under a kilometer — at closing speeds around 10 km/s.
CRASH Clock — a stress gauge: the expected time until a possible collision if every satellite stopped maneuvering. Shorter clock = less room for error. It is not a prediction that a collision will happen. The authors publish the live value at the Outer Space Institute's CRASH Clock page. "Possible collision" here means a pass within the combined hard-body size of two representative objects — the method's "10-5-10" convention: 10 m and 5 m spacecraft, 10 cm debris — not a certainty of impact.
f_imp — the assumed fraction of dangerous close passes that become actual collisions. Nobody has measured it (the zero-event record verifiably cannot pin it), so the study treats it as an assumption and flags every trajectory magnitude as conditional on it — "f_imp-conditional" means "scales with that assumption."
Kessler syndrome — a condition where collisions create debris faster than the atmosphere removes it, so each crash makes the next more likely. Even when triggered, it unfolds over decades — a slow-motion runaway, not a movie explosion. In this study the word is always band-qualified: at 700–1,000 km it names an effectively irreversible ratchet; at 465–495 km the honest terms are "fuel-limited transient cascade" and "operational saturation" — severe, but not forever.
Phase mixing — how long a tidy, slot-managed constellation would take to smear into random positions if control stopped — the crux of the 0.71-vs-1.75-day bracket in §3.

Methods & reproducibility

Every number above traces to: the Space-Track catalog snapshot (2026-07-15, 32,010 objects); the House-of-Cards v3 method, independently reimplemented and validated against its published values; seeded simulations (seed 20260715, n = 100,000) with raw draw vectors shipped; and the live workbook (0 formula errors). The full Floor — engines, results, draws, workbook, specification — publishes with the study. If a number here and a number in those files disagree, the files win — and we want to know.

Notes

  1. Occupancy census: J. McDowell, GCAT — General Catalog of Artificial Space Objects (epoch 8 Jul 2026): 10,736 active Starlink of 16,234 active payloads, 2,113 of them non-maneuverable.
  2. S. Thiele, Heiland, Boley & Lawler, "An Orbital House of Cards," arXiv:2512.09643 (v3) / Acta Astronautica (2026); live figure at the Outer Space Institute CRASH Clock (164 d 2018 → 5.5 d Jun 2025 → 2.5 d May 2026). We cite the v3 5.5-day figure, not the earlier press number.
  3. COMSPOC: post-maneuver orbit-prediction error up to 40 km over several days (carried via n.2).
  4. SpaceNews, 16 Dec 2025, with SpaceX (Nicolls) statements 12–13 Dec 2025: a CAS Space Kinetica-1 satellite passed within 200 m of Starlink-6079 (NORAD 56120) at 560 km, "no coordination"; CAS Space counters that trajectory data were shared ~14 min before closest approach.
  5. Nicolls (SpaceX), 1 Jan 2026: lowering ~4,400 satellites 550→480 km through 2026, cited as a safety reconfiguration.
  6. The two-currencies distinction rests on primary rule texts and the docket, not on a memo: the ITU Radio Regulations RR 11.44 / 11.44C, the FCC processing-round orders, and the OST's bar on title to space itself (n.17). Filing sequence and identifiers at n.15.
  7. Deployment milestones: ITU Res. 35 (WRC-19); 47 CFR 25.164 (50% in 6 yr, 100% in 9) and 25.165 (surety bond forfeited on a missed milestone or on surrender).
  8. Deployment-race model — this study's own engine: race_model_d3b.py, seed 26716, 2,000-row raw sweep shipped and reproduced byte-identically; all payoffs are assumed and swept, so the region shares are shares of the assumed box, not probabilities. Engine and draws ship in the Floor.
  9. A. Rao, D. Burgess & D. Kaffine, "Orbital-use fees could more than quadruple the value of the space industry," PNAS (2020): dynamic optimal fee ≈ $235k/sat-yr by 2040; removal without incentive reform recovers ≤ 9.5% of lost value. Reinforced by A. Rao & G. Rondina, "The Economics of Orbit Use: Open Access, External Costs, and Runaway Debris Growth," JAERE 12(2) (2025) (preprint): fully internalizing the launch externality is still insufficient under autocatalytic debris growth. Our static fee (≈ $231/sat-yr) is a floor on their dynamic figure, not an estimate of it.
  10. Occupancy and density are measured from the U.S. Space Force Space-Track element catalog (full pull 15 Jul 2026, 32,010 objects): the five bases (38.7% of tracked LEO objects, 66.1% of active payloads, 95.0% of the 465–495 km density, 97.9% of the modeled no-maneuver collision rate), OneWeb's 654, and the 10,742 Starlink name-lines.
  11. Mass-share base: J. Bennett & N. Cudney, "Holding up the skies," Territory, Politics, Governance (2026) — 52.0% of operational-satellite mass in LEO (underlying census May 2023, stale-flagged); it is not a share of all mass in orbit, which is where the source's own abstract slipped.
  12. Maneuver counts: SpaceX FCC semiannual constellation reports (144,404 Dec 2024–May 2025; 148,696 Jun–Nov 2025, ≈ 800/day), via Space Intel Report.
  13. The published runaway threshold is for the higher shells: H. Lewis & D. Kessler, "Critical Number of Spacecraft in Low Earth Orbit," Proc. 9th European Conf. on Space Debris (Bonn, 2025), paper 305 — at or above threshold 520–1000 km. It does not speak to the 480-km shell; every 480-km criticality figure here is ours, modeled.
  14. Natural infall: J. Rojas, J. Duprat et al., "The micrometeorite flux at Dome C (Antarctica)," Earth and Planetary Science Letters 560 (2021), 116794 — ~15,000 t/yr of meteoric material entering the atmosphere (method-to-method range ~2,000–110,000 t/yr).
  15. Reentry-metal deposition: D. Murphy et al., PNAS 120(43) (2023), e2313374120 — ~10% of stratospheric aerosol particles > 120 nm carry reentry metals; for Li, Al, Cu and Pb the reentry-attributed mass already exceeds the meteoric source at today's fleet size (direct aircraft sampling, measured).
  16. The 2026 filing docket (FCC ICFS): SpaceX ODC SAT-LOA-20260108-00016 (accepted DA-26-113); Blue Origin "Project Sunrise" SAT-LOA-20260310-00118; Orbital Compute SAT-LOA-20260624-00251; SpaceX Gen3 SAT-LOA-20260630-00264; petitions to deny by Amazon, Blue Origin and Viasat (6 Mar).
  17. Active-removal frontier: JAXA CRD2 (rendezvous with a non-cooperative upper stage; observation only, no capture) and Astroscale ADRAS-J (a ~15 m approach with an autonomous abort before capture, Dec 2024). No pre-existing derelict has been removed by a third-party servicer as of mid-2026.
  18. Occupation without title: Outer Space Treaty, Arts. II, VI, IX (no national appropriation; state responsibility and continuing supervision). Seed observation: A. Lawler & A. Boley, The Conversation, 13 Jul 2026.
  19. The continuity-regime (E6) analogs are demonstrated instruments in other domains: bank Prompt Corrective Action (12 U.S.C. §1831o), officer certification under penalty (SOX §906, 18 U.S.C. §1350), the nuclear-decommissioning trust (NRC 10 CFR 50.75), resolution plans (Dodd-Frank Title I) and an orphan-tail levy (SMCRA Abandoned Mine Land). The ≈ $71k per-satellite disposal unit cost and the ~$759M census trust principal are this study's engine outputs (Floor).
The floor beneath this study

Everything you need to check us

Every study here has a surface a non-specialist can read, and a floor directly beneath it with the numbers, code, and assumptions a specialist needs to trust it. This is the floor. Every engine runs from a fixed seed recorded in its row below and ships its results record and raw draw sample, so any reported statistic recomputes without trusting ours.

Which engines produced the published numbers

kessler_qb_engine.py (v1.2) produced the criticality and trajectory results; multishell_run.py the §3 clock numbers; race_model_d3b.py the §4 race map; kessler_reentry_mass.py the Interlude’s reentry-mass bracket; kessler_stakes_build.py the ground-stakes table; and d15_e6_trust_sizing.py / d15d_staged_resize.py — written by the Economics & Statistics Referee seat as an independent reimplementation on a fresh seed — the E6 trust-principal floor.

Every stochastic engine above was checked cross-seed during review, and the deviations are recorded inside the results files themselves; the race sweep was additionally reproduced byte-identically. The interactive machines’ baked data blobs descend from these files — byte-for-byte, which is what the audit trail verifies.

If a number in the report and a number in these files disagree, the files win — and we want to know. That is what the next box is for.

Found a discrepancy?

Hold this study to the standard it holds others to.

This page prints its own house rule: if the page and a data file disagree, the file wins. The same rule extends to you. If a number here fails to trace — to the catalog, to a cited source, to a seeded draw vector in the floor above — be specific, cite something, and we’ll do the work. If you’re right, we amend the study and log the change in the open, with credit if you want it.

Flag a discrepancy →